CRESCENTHARVEST is a cyberespionage-oriented malware campaign targeting Farsi-speaking individuals associated with or interested in Iranian protest activity. It uses protest-themed decoy material and malicious Windows shortcut files masquerading as media to induce execution. The infection chain deploys browser-key theft and remote-access/information-stealing components through DLL sideloading, establishes event-triggered scheduled-task persistence, and displays decoy content to reduce suspicion. The malware steals browser credentials, cookies, browsing history, Chrome app-bound encryption material, Telegram Desktop session data, host and security-product information, and keystrokes; it also supports command execution and exfiltration over HTTPS. The activity has been assessed as potentially Iran-aligned based on victimology and tradecraft, with noted similarities to activity associated with Educated Manticore, which overlaps reporting on APT42/Charming Kitten/Mint Sandstorm. Attribution to a named nation-state actor or threat group remains unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously reported dissident-focused campaign used only as a comparison point. It reportedly used LNK files, payload carving from LNKs, DLL sideloading, a backdoor, and custom command-and-control infrastructure.
Referenced as a named activity cluster amplifying the conflict via phishing, data theft, and server exploitation.
Named as part of the pre-existing APT landscape active prior to Feb 28; associated activity described as phishing, exploitation of public servers, and information theft targeting Israeli, US, and regional networks.
Named activity cluster referenced in Iran-linked pre-conflict cyber campaigns using phishing, server exploitation, and information theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.